When the algorithm fails

The same pattern is now emerging in the digital supply chain. In June 2024, the Qilin ransomware group attacked Synnovis, the pathology provider serving NHS and private patients across several major London trusts25. Within hours, blood testing systems across King’s College Hospital, Guy’s and St Thomas’, Princess Royal University Hospital and others were offline. More than 11,000 outpatient and elective appointments were delayed26, and 1,134 planned operations were cancelled in the first 13 days at two trusts alone27. By November 2025, when Synnovis completed its forensic notification process, data potentially relating to almost an estimated one million patients had been identified as having been taken28.

The Synnovis attack is one of the clearest recent examples of how patient safety risk is migrating into the IT supply chain. When a pathology system fails, clinical decisions that depend on test results cannot be made safely. When the failure lasts not for hours but for weeks, the care consequences become clinically significant. The liability chain does not stop at the hospital firewall.

The Information Commissioner’s Office (ICO) made that point in practical terms with its £3.07 million fine against Advanced Computer Software, the provider of NHS 111’s patient management system, following a 2022 ransomware attack29. Advanced had failed to implement multi-factor authentication across its systems, a basic security control. The ICO’s John Edwards described the shortfall as a serious failure by an organisation processing large volumes of sensitive data30. The fine was the first imposed by the ICO on a data processor under UK GDPR, and its importance extends beyond the amount. It confirmed that third-party IT suppliers to healthcare organisations are directly exposed to regulatory enforcement, and that weak cyber governance has consequences across the supply chain.

For private hospital groups, the question is obvious: how well do you understand the cyber governance posture of every supplier whose failure could harm patients or disrupt care pathways?

AI is adding a further dimension. Ambient AI scribes, which listen to consultations and generate structured notes, are now being deployed in some NHS and private settings. NHSE published guidance in January 2026 establishing a register of self-certified suppliers31, while the tools themselves are, in many cases, regulated as Class I medical devices by the MHRA32. The regulatory perimeter remains unsettled. The National Commission into the Regulation of AI in Healthcare, whose call for evidence findings were published by the MHRA in June 2026, found that the current framework — designed for static medical devices — is not well suited to iterative and adaptive AI systems33. The MHRA’s AI Airlock sandbox, now in its third phase following the completion of Phase 2 in May 2026, is the primary mechanism through which those gaps are being identified and addressed, with formal guidance yet to follow34.

Lawton et al., writing in the Future Healthcare Journal in 2024, identified the liability issue with precision: clinicians risk becoming ‘liability sinks’ for AI — absorbing legal responsibility for decisions shaped by systems they do not and cannot fully understand35. A 2025 whitepaper from the same research group, drawing on trials of six AI decision-support tools, found that this perceived burden of liability was the greatest single threat to clinical adoption of AI in healthcare36. When an ambient scribe generates an inaccurate note that a pressured clinician does not review carefully, or when a clinical decision support tool recommends a course of action that later proves wrong, the practitioner who relied on the output, and the organisation that deployed the system without adequate governance, is likely to face the claim. The developer of the algorithm is, in the current legal environment, much harder to reach.